What's changed: Created Associate Google Workspace Administrator Chapter 3 (Domain 3 "Governance/compliance": data retention and eDiscovery = Vault retention rules/holds (override deletion)/search-export; data protection = DLP detect-block/data regions/trust rules/label classification).
3.2Data protection and compliance (DLP, data regions)
Understand data loss prevention (DLP) rules to detect sensitive data (e.g., credit card numbers) and block sharing, data regions to control storage location geographically, trust rules to govern sharing with external organizations, and classification with labels.
After retention comes preventing sensitive data from leaking out and meeting regulations on where it is stored. DLP, data regions, and trust rules handle this.
3.2.1DLP (data loss prevention)
A DLP rule detects sensitive data (predefined detectors like credit card numbers or SSNs, or custom patterns) in Gmail/Drive content and can warn or block external sharing/sending. Map "prevent sensitive data leaking outside = DLP rule." Define detection targets and action (block/audit/warn) in the rule.
3.2.2Data regions, trust rules, and labels
Data regions confine stored data to a geography (e.g., US/EU) to meet residency regulations. Trust rules define which external organizations (domains) sharing is allowed/restricted with, governing external sharing. Labels classify files (e.g., confidential) and, combined with DLP and sharing controls, change how they are handled. Map "control storage location by geography = data regions," "allow sharing only with specific domains = trust rules," "classify as confidential = labels."
Common: requirement → means. E.g., "block external sharing of files with card numbers" = DLP rule; "store data within Europe" = data regions; "allow sharing only with a partner domain" = trust rules; "classify as confidential and change handling" = labels.
Watch the mix-ups: (1) DLP is content-based detect/block, while trust rules are domain-based sharing permission—different axes. (2) Data regions are about storage location, distinct from keys or DLP. (3) Advanced compliance features depend on edition/license.
3.2.3Section summary
- DLP rules = detect sensitive data and warn/block external sharing/sending (content-based)
- Data regions = control storage geography; trust rules = govern sharing with external domains
- Classify files with labels and combine with DLP/sharing controls
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To auto-detect and block external sharing of files containing credit card numbers, what do you use?
Q2. To confine stored data within Europe for compliance, what do you use?
Q3. To allow file sharing only with a specific partner domain and block others, what do you use?
Q4. Which correctly contrasts DLP rules and trust rules?
Q5. To classify files as "confidential" and change handling combined with DLP/sharing controls, what do you use?
Q6. On what does the availability of advanced compliance features (Vault, DLP, data regions) mainly depend?

